Impact
A flaw in cockpit-machines allows a local attacker who can inspect running processes to see guest virtual machine credentials, such as rootPassword and userPassword, that are passed as a JSON argument during VM creation or installation. The exposure lasts only while the installation workflow runs and depends on the host’s process‑visibility permissions, but it enables an attacker to obtain credentials for the VM while the installation is active.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 9 and RHEL 10 systems that run cockpit-machines. No specific minor or patch level is listed, so any version of cockpit-machines installed on those RHEL releases may be vulnerable.
Risk and Exploitability
The CVSS score is 5, indicating moderate severity. No EPSS score is available and the vulnerability is not in CISA’s KEV catalog. The likely attack vector is a local attacker who can view processes; such an attacker can read the process command line to retrieve the exposed credentials. Because the exposure is temporary and requires prior installation activity, the window of opportunity is limited, but the impact includes compromise of VM authentication data.
OpenCVE Enrichment